CVE-2026-58494

Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI guest with a read-only source file capability to overwrite host files exposed as FilePerms::READ through wasip1, wasip2, or wasip3 filesystem interfaces. This issue is fixed in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1.
Configurations

No configuration.

History

08 Jul 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 21:16

Updated : 2026-07-10 19:10


NVD link : CVE-2026-58494

Mitre link : CVE-2026-58494

CVE.ORG link : CVE-2026-58494


JSON object : View

Products Affected

No product.

CWE
CWE-281

Improper Preservation of Permissions

CWE-863

Incorrect Authorization